CISCO has announced the public disclosure of two unpatched vulnerabilities, CVE-2026-20354 and CVE-2026-20355, affecting its Secure Email product. These medium-severity issues can allow attackers to intercept and modify email traffic. Cisco advises that devices running AsyncOS version 16.5.0 or earlier with S/MIME enabled are at risk, but they are not currently aware of any real-world exploitation.
Additionally, Cisco has released patches for critical vulnerabilities in IOS XR and Nexus 9000 series switches, which could lead to severe attacks such as remote code execution. Other notable patches address vulnerabilities in several phone series that could cause denial-of-service conditions.